Skip to content

feat(goal-kernel): add bounded Codex experiment with revalidated acceptance - #5485

Closed
songoow wants to merge 3 commits into
mainfrom
codex/goal-kernel-verification
Closed

songoow wants to merge 3 commits into
mainfrom
codex/goal-kernel-verification

Conversation

@songoow

@songoow songoow commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

Introduce an explicitly invoked Codex experiment whose completion and progress follow fresh acceptance checks. The earlier prototype could declare completion after a previously accepted artifact was deleted, count repeated claims or new plans as progress, and reject success on the final permitted turn.

This package rechecks acceptance at turn boundaries, revokes stale passes, reopens affected todos, credits each checkpoint once across restarts, and settles completion before resource exhaustion while retaining integrity and owner-decision holds. It also catches in-turn goal edits, rejects repeated CLI initialization and prevents owner acceptance from bypassing automatic checks.

  • Basis: the bounded prototype reliability request in this PR; no existing public issue is closed.
  • Intended base: main.
  • Placement: independently invoked private TypeScript experiment under packages/; Codex CLI provides execution. No runtime import, capability registration, native Goal API integration, or frontend/Lark entrypoint is introduced.

Author Declaration

  • Written by: model_agent — OpenAI Codex (GPT-6 family), adapting an existing prototype.
  • Specification: packages/loopx-goal-kernel/CONTRACT.md at this PR head.
Criterion Disposition Implementation Evidence
Current acceptance, distinct progress and budget-edge completion implemented verify.ts, state.ts, kernel.ts reliability counterexamples and five-turn live smoke
CLI use and state readback implemented cli.ts, view.ts real CLI subprocess tests; live status/view
Long-horizon improvement over native execution deferred existing long-horizon research program matched multi-hour/task evaluation remains unqualified
Production/frontend integration out_of_scope independent experiment only no references from loopx/ or apps/

Change And Validation

Check Result What it establishes
npm test in the package 57 passed acceptance regression, idle accounting, terminal precedence, goal integrity, owner decisions, legacy state and CLI behavior
npm run typecheck passed strict TypeScript checking across implementation/tests/live smoke
npm run test:live -- --sandbox danger-full-access passed real Codex CLI 0.160.0: five process invocations, one resumed session, externally regressed artifact repaired without duplicate credit, last-turn success and stale-success rejection
Public boundary scan passed source/docs/examples/metadata exclude credentials, private runtime artifacts and machine paths
Repository semantic smoke passed registered shared vocabularies and ownership checks
Semantic advisory scope limitation current tool scans loopx/, rejects explicit packages/ input; the vocabulary remains package-local and is manually reviewed

The final live replay and repository semantic smoke both passed. The first live attempt used an unauthenticated inherited CLI configuration and failed before work; the successful run used the existing authenticated configuration. No credentials or global settings were modified.

The controlled live task deliberately requests one checkpoint per turn. It proves protocol and regression behavior, not hours-long reliability, model-quality uplift, or lower cost. Concurrency, crash transactions, provider accounting, general recovery and sandboxed verifier independence remain explicitly unqualified. Automatic checks execute trusted owner-provided commands and may run twice per turn.

Boundary And Review Notes

  • UI impact: none in shipped LoopX; the experiment has CLI/text readback only. Product integration remains outside this slice, not implied complete.
  • Typed ownership: state.ts now owns mutations previously mixed into the text renderer. acceptance_regressed and optional v1 credited_predicates remain local to this experiment.
  • Default behavior: no shared runtime changes. Offline CI runs only for the package/workflow paths; live checks are explicit and spend model tokens.
  • Future-facing pass: separated acceptance mutation from rendering; removed duplicate smoke/example coverage and unsupported guarantee claims.
  • All commits carry DCO sign-off. No benchmark task data, logs, trajectories, credentials or local state are included.
  • Maintainer merge required; this PR will not be self-merged.

Signed-off-by: song <liusongstep@gmail.com>
Signed-off-by: song <liusongstep@gmail.com>
@songoow
songoow requested a review from huangruiteng as a code owner October 2, 2026 17:30
@songoow songoow closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant